Coping with "Signing certificate has been revoked" exceptions
Last week, after installing some of the various patches available
via smpatch/updatemanager, two of our machines (one sparc, one x86)
began to regularly fail to be able to retrieve patches. And /var/adm/messages
contained exceptions for example:
Sep 14 16:30:04 altair root: [ID 702911 user.crit] => com.sun.patchpro.server.ServerPatchServiceProvider@c62080 <=Signing certificate has been revoked.: 335544443
To work around this, I had to re-install the transport certificate update patch
(122232/122231) from february. (I'm sure it was a re-install, since I
had to remove it before it was successfully installed).
Is there any know reason that this should have happened, so I can
avoid it happening again?
# 2
Here is a list of ls -t /var/sadm/patch, starting with most recent
and ending with those installed September 7th. My guess is that
problems started with the batch on September 11.
drwxr-xr-- 2 root root 512 Sep 15 15:46 121020-03
drwxr-xr-- 2 root root 512 Sep 15 15:45 121022-01
drwxr-xr-- 2 root root 512 Sep 15 15:41 120740-03
drwxr-xr-- 2 root root 512 Sep 15 15:41 119369-05
drwxr-xr-- 2 root root 512 Sep 15 15:29 122232-01
drwxr-xr-- 2 root root 512 Sep 15 14:26 121119-06
drwxr-xr-- 2 root root 512 Sep 14 14:06 120544-05
drwxr-xr-- 2 root root 512 Sep 11 12:10 120630-03
drwxr-xr-- 2 root root 512 Sep 11 12:10 121013-02
drwxr-xr-- 2 root root 512 Sep 11 12:10 119060-16
drwxr-xr-- 2 root root 512 Sep 11 12:10 120468-05
drwxr-xr-- 2 root root 512 Sep 11 12:09 119279-11
drwxr-xr-- 2 root root 512 Sep 11 12:09 119811-03
drwxr-xr-- 2 root root 512 Sep 11 12:09 120411-15
drwxr-xr-- 2 root root 512 Sep 8 07:01 120037-07
drwxr-xr-- 2 root root 512 Sep 7 12:44 119118-22
drwxr-xr-- 2 root root 512 Sep 7 12:44 118344-13
drwxr-xr-- 2 root root 512 Sep 7 12:43 119704-06
drwxr-xr-- 2 root root 512 Sep 7 12:43 119082-23
drwxr-xr-- 2 root root 512 Sep 7 12:43 119535-09
drwxr-xr-- 2 root root 512 Sep 7 12:43 118880-02
# 3
Going through the patches listed, I can't see anything which would interfere with the Sun Update certificates, there has been no report of similar issues at Sun Update support either.
I can only really suggest that if it happens again, keep a copy of
/usr/lib/cc-cfw/platform/transport/etc/CACert.pem
before re-installing the 122232/122231 patch, and see if anything has changed in the file.